CVE-2024-21725: [20240204] - Core - XSS in mail address outputs
Published Feb 20, 2024
·Updated
Inadequate escaping of mail addresses lead to XSS vulnerabilities in various components.
Affected Software
2 affected components
Joomla Joomla\!>=4.0.0<4.4.3
Joomla Joomla\!>=5.0.0<5.0.3
Event History
Feb 20, 2024
CVE Published
via MITRE·04:22 PM
Data Sourced
via MITRE·04:22 PM
DescriptionWeakness
Feb 21, 2024
News Published
via BleepingComputer·10:55 PM
News Published
via BleepingComputer·10:56 PM
Feb 29, 2024
Data Sourced
via NVD·01:44 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-21725?
The severity of CVE-2024-21725 is classified as high due to its XSS vulnerabilities that could lead to remote code execution.
2
How do I fix CVE-2024-21725?
To fix CVE-2024-21725, update your Joomla installation to version 4.4.4 or later, or version 5.0.4 or later.
3
What versions of Joomla are affected by CVE-2024-21725?
CVE-2024-21725 affects Joomla versions 4.0.0 to 4.4.3 and 5.0.0 to 5.0.3.
4
What are the consequences of exploiting CVE-2024-21725?
Exploiting CVE-2024-21725 may allow attackers to execute arbitrary JavaScript code in users' browsers, leading to data theft or site compromise.
5
Is there a workaround for CVE-2024-21725?
There are no effective workarounds for CVE-2024-21725; upgrading to the latest version is the recommended action.